VendorsD-Linkdsl-7740c_firmware6.tr069.20211230
Vulnerabilities

D-Link DSL-7740C Firmware 6.tr069.20211230

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2025-29515
Incorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to modify arbitrary settings within the device's XML database, including the administrator’s password.
Published 2025-08-25 · Analyzed
9.8EPSS 0.006
CVE-2025-29514
Incorrect access control in the config.xgi function of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to download the configuration file via providing a crafted web request.
Published 2025-08-25 · Analyzed
9.8EPSS 0.006
CVE-2025-29516
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the backup function.
Published 2025-08-25 · Analyzed
7.2EPSS 0.021
CVE-2025-29523
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping6 function.
Published 2025-08-25 · Analyzed
7.2EPSS 0.021
CVE-2025-29517
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the traceroute6 function.
Published 2025-08-25 · Analyzed
6.8EPSS 0.016
CVE-2025-29522
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping function.
Published 2025-08-25 · Analyzed
6.5EPSS 0.014
CVE-2025-29519
A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to execute arbitrary commands via supplying a crafted GET request.
Published 2025-08-25 · Analyzed
5.3EPSS 0.017
CVE-2025-29521
Insecure default credentials for the Adminsitrator account of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to escalate privileges via a bruteforce attack.
Published 2025-08-25 · Analyzed
5.3EPSS 0.006
CVE-2025-29520
Incorrect access control in the Maintenance module of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows authenticated attackers with low-level privileges to arbitrarily change the high-privileged account passwords and escalate privileges.
Published 2025-08-25 · Analyzed
5.3EPSS 0.006